Bitsight Data and the Splunk Common Information Model Mapping

Bitsight findings are mapped to the Splunk Common Information Model, which links the Bitsight findings to default views in Splunk.

Compromised Systems 
Risk Vector

Splunk Model: Intrusion Detection, Malware

 

Open Ports, Web Application 
Headers, and Server Software 
Risk Vectors

Splunk Model: Endpoint, Ports

 

TLS/SSL Certificates Risk Vector

Splunk Model: Certificates

 

Critical Vulnerability 
Management Risk Vector

Splunk Model: Vulnerabilities

 

Potentially Exploited and 
Insecure Systems Risk Vectors

Splunk Model: Web

 

SPF Domains, DKIM Records, 
and DNSSEC Risk Vectors

Splunk Model: Network Resolutions (DNS)
 

Publish Date or Recent Edits
  • February 3, 2023: Removed Security Incidents and Exposed Credentials from included risk vectors.
  • July 10, 2020: Published.
Was this article helpful?
0 out of 1 found this helpful

Comments

0 comments

Please sign in to leave a comment.